Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165F27224A1340E3A40DFB3F4E1A43FD5A1DB8363C69AAFD4A1DEA4651FD4D89878721C |
|
CONTENT
ssdeep
|
384:oQEaTI7jDBCL3hbhSfxM04jdgsBe3m9vdFwkGs8u5FvOCDbhnd+j:oQEaT0/BSxbCEEmTFwvs8h0bhnMj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ca2245d77339acb |
|
VISUAL
aHash
|
077f7f0718181810 |
|
VISUAL
dHash
|
7ff7addd72333232 |
|
VISUAL
wHash
|
0fffff0f18181818 |
|
VISUAL
colorHash
|
38000c00010 |
|
VISUAL
cropResistant
|
abab2b7b5b2a3263,7ff7addd72333232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4482 techniques to evade detection by security scanners and make reverse engineering more difficult.